No more typing reviews! Try our Samantha, our new voice AI agent.

CucumberStudio vs Veracode comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CucumberStudio
Ranking in Dynamic Application Security Testing (DAST)
11th
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
12
Ranking in other categories
Rapid Application Development Software (24th)
Veracode
Ranking in Dynamic Application Security Testing (DAST)
1st
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (2nd), Container Security (8th), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Application Security Posture Management (ASPM) (1st)
 

Mindshare comparison

As of March 2026, in the Dynamic Application Security Testing (DAST) category, the mindshare of CucumberStudio is 1.3%, up from 0.2% compared to the previous year. The mindshare of Veracode is 17.2%, down from 29.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Mindshare Distribution
ProductMindshare (%)
Veracode17.2%
CucumberStudio1.3%
Other81.5%
Dynamic Application Security Testing (DAST)
 

Featured Reviews

AK
Manager in Quality and Processes at a transportation company with 1,001-5,000 employees
Action words streamline test case management and boost integration with project tools
The most valuable feature of CucumberStudio is its use of action words, which allows me to avoid writing test cases from scratch for the most common scenarios. Moreover, CucumberStudio's support for code integrations and API calls is excellent. The platform provides the benefit of unlimited read-only accounts, enabling various roles like engineers and product managers to review test cases and results. The structure of CucumberStudio is also commendable, as it supports BDD style Gherkin syntax, which is useful for our test management processes.
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CucumberStudio has a very user-friendly interface."
"Hiptest is a great test management tool for agile teams."
"Integration with automation frameworks, keywords, and tags allows for saving time writing test cases and implementing automation."
"The data table that helps in converting a single script to multiple test cases is very helpful."
"The most valuable feature of CucumberStudio is its use of action words, which allows me to avoid writing test cases from scratch for the most common scenarios."
"The power of Hiptest is its test cases and campaign management."
"The best thing is that a person without knowledge about the program can easily understand what happened in our testing process."
"CucumberStudio aligns with our strategy for data-driven testing."
"Static, dynamic, and manual scan features were all very useful for us and helped us fix many security flaws."
"The security team can track the remediation and risk acceptance statistics."
"The product’s policy reporting for ensuring compliance with industry standards and regulations is great."
"The policy reporting for ensuring compliance with industry standards and regulations is pretty comprehensive, especially around PCI. If you do the static analysis, the dynamic analysis, and then a manual penetration test, it aggregates all of these results into one report. And then they create a PCI-specific report around it which helps to illustrate how the application adheres to different standards."
"The most valuable feature is the security and vulnerability parts of the solution. It shows medium to high vulnerabilities so we can find them, then upgrade our model before it is too late. It is useful because it automates security. Also, it makes things more efficient. So, there is no need for the security team to scan every time. The application team can update it whenever possible in development."
"Based on Veracode recommendations, I work with the dev team and remediate the flaw, and that's something that I would probably have missed if I did only the manual code review."
"I like the way the flaws are reported in the system."
"Tech support is outstanding. Best in class. Absolutely. They bend over backwards to help us. We'll come up with questions and within minutes, we'll get answers. It's amazing. It's truly amazing."
 

Cons

"I think it would be better if we could also do the reporting with CucumberStudio."
"It needs some improvement when exporting scenarios into automation code, to make it easier to manage the repeatable action words and tests."
"A key area for improvement is to revamp outdated components such as HipTest publisher."
"A key area for improvement is to revamp outdated components such as HipTest publisher."
"The reporting needs to be improved."
"Yes, it is not stable when you create a data table that includes more than 30 elements, so it can lose your data."
"More tutorials and examples."
"CucumberStudio's API integration could be improved both in terms of reliability and design."
"The overall reporting structure is complicated, and it's difficult to understand the report."
"Calypso (our application) is large and the results take up to two months."
"The static scans on Java lack microservices architecture scanning. We have developed an in-house pattern for this and the scans can't take care of it as a single entity."
"The only notable problem we have had is that when new versions of Swift have come out, we have found Veracode tends to be a bit behind in updates to support the new language changes."
"Veracode would benefit greatly from more training resources. The videos are great, but I would like more hands-on training writing a script, validating a script with a unit test in a different language, etc. That's something that would be very valuable."
"Their scanning engine is sometimes a little bit slow. They can improve the scan time."
"It can take time to find options if you don’t use the interface a lot. At some point, a bit of interface restyling may help."
"There are many times when their product goes to check my code and it dies, and I don't know why. I've contacted support and they're not really helpful with this particular problem. I go to the logs and I look at what I can but I can't tell why the check process has essentially just died in the middle of checking."
 

Pricing and Cost Advice

Information not available
"We use this product per project rather than per developer... Your development model will really determine what the best fit is for you in terms of licensing, because of the project-based licensing. If you do a few projects, that's more attractive. If you have a large number of developers, that would also make the product a little more attractive."
"I wouldn't really recommend Veracode for a small firm, because it might be a little pricey for them. But for a large organization, with more than 1,000 applications in the enterprise, there are tiered levels of pricing."
"The worst part about the product is that it does not scale at all. Also, microservices apps will cost you a fortune."
"The pricing and licensing are reasonable, and relatively straightforward, and different licensing and subscription models are available."
"For our company, the price is reasonable for the benefits that we get."
"They have just streamlined the licensing and they have a number of flexible options available, so overall it is quite good, albeit pricey."
"Negotiate some, but their prices are reasonable."
"I don't have firsthand knowledge of Veracode pricing, but based on client feedback, it seems to be expensive with additional fees for certain features."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
885,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
25%
Manufacturing Company
17%
Marketing Services Firm
8%
Transportation Company
8%
Financial Services Firm
16%
Computer Software Company
12%
Manufacturing Company
11%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise3
Large Enterprise4
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise45
Large Enterprise114
 

Questions from the Community

What needs improvement with Hiptest?
CucumberStudio's API integration could be improved both in terms of reliability and design. The API requires data to be sent in a specific format, which takes time to build. Additionally, the repor...
What is your primary use case for Hiptest?
I use CucumberStudio as a test case repository. All of our test cases are stored there. It is also part of our test planning process. For every sprint, we plan the test cases in CucumberStudio and ...
What advice do you have for others considering Hiptest?
For teams following a BDD style software development approach, CucumberStudio is a great collaborative tool that covers all the basic requirements of a test management tool. I would rate CucumberSt...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabilities.
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Comparisons

 

Also Known As

Hiptest
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

Cisco, Cardinal Health, Intuit, Smartbox, Accenture, Deliveroo
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about CucumberStudio vs. Veracode and other solutions. Updated: February 2026.
885,311 professionals have used our research since 2012.